What a Hash Tells You
A hash turns any input into a fixed-length fingerprint: SHA-256 of "abc" is always ba7816bf...f20015ad, 64 hex characters, while MD5 gives 32 and SHA-512 gives 128. Type text or drop a file above to get MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once, switch on HMAC to add a secret key, or paste a published hash to compare.
The same input always gives the same hash, and changing a single character changes the whole output. That makes a hash a quick way to check that a file or message has not changed. Hashing here runs in your browser with the Web Crypto API (MD5 with a small JavaScript routine), so the text and files you hash are not uploaded.
Test Vectors to Check Any Hash Tool
These are the standard published values. Type abc above and the tool should show exactly the middle column. The empty-string column is worth recognizing: if your own code prints one of these, it hashed nothing.
| Algorithm | "abc" | "" (empty) |
|---|---|---|
| MD5 | 900150983cd24fb0d6963f7d28e17f72 | d41d8cd98f00b204e9800998ecf8427e |
| SHA-1 | a9993e364706816aba3e25717850c26c9cd0d89d | da39a3ee5e6b4b0d3255bfef95601890afd80709 |
| SHA-256 | ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
| SHA-512 | ddaf35a193617abacc417349ae20413112e6fa4e89a97ea20a9eeee64b55d39a2192992a274fc1a836ba3c23a3feebbd454d4423643ce80e2a9ac94fa54ca49f | cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e |
Which Algorithm to Use
| Algorithm | Output | Hex length | Status | Fine for |
|---|---|---|---|---|
| MD5 | 128 bits | 32 | Broken: collisions can be made on a laptop | Spotting accidental corruption, cache keys |
| SHA-1 | 160 bits | 40 | Broken: public collision in 2017; NIST plans to retire it by the end of 2030 | Legacy systems, Git object IDs |
| SHA-256 | 256 bits | 64 | Secure | Download checksums, signatures, HMAC |
| SHA-384 | 384 bits | 96 | Secure | TLS suites and policies that require it |
| SHA-512 | 512 bits | 128 | Secure | Same uses as SHA-256, with a longer output |
None of these is a password hash. Stored passwords need a slow, salted function such as Argon2id, bcrypt or scrypt.
Why Your Hash Does Not Match
Hashes are exact to the byte, so a mismatch almost always means the input differs, not the algorithm.
- A trailing newline.
echo abc | sha256sumhashes "abc" plus a line break and prints edeaaff3...0efd18cb, not ba7816bf...f20015ad. Useprintf 'abc'orecho -n abc. - Windows line endings. "abc" followed by CRLF hashes to 552bab68...85fdb025. A text file edited on Windows and on Linux can differ only in this.
- Case and spaces. "ABC" and "abc " (with a space) give completely different hashes. The hex output itself is not case-sensitive, and the Compare box ignores case.
- Text vs file. Pasting a file's contents into the text box is not the same as dropping the file: the file may have a byte order mark or a final newline you cannot see.
- HMAC vs plain hash. A webhook signature is an HMAC; it only matches when the same secret key is used.
An HMAC you can check
With HMAC mode on, key key and the message The quick brown fox jumps over the lazy dog, HMAC-SHA256 is f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8 and HMAC-SHA1 is de7c9b85b8b78aa6bc8a7a36f70a90701c9db4d9.
To encode the raw bytes of a hash or a file as text rather than hex, use the Base64 encoder.
Hash Generator Guide
185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969, completely different from SHA-256 of "hello" (lowercase). Hash functions are used for data integrity verification, password storage, digital signatures, and blockchain.bcrypt.hash(password, 12). In Python: bcrypt.hashpw(password, bcrypt.gensalt(12)).sha256sum file.iso (Linux/macOS) or Get-FileHash file.iso -Algorithm SHA256 (PowerShell). This process is called hash verification or checksum verification. It detects corrupted downloads and tampering, but not sophisticated attacks where the hash itself was also replaced: always verify hashes from the official publisher's site, not just the download mirror.crypto.subtle.digest('SHA-256', buffer) for SHA-2 family hashes and crypto.subtle.importKey() + crypto.subtle.sign() for HMAC. MD5 is not included in the Web Crypto API (it is cryptographically broken) so MD5 is computed using a pure JavaScript implementation. Benefits of Web Crypto: it runs natively in the browser sandbox, your data never leaves your device, and the implementations are battle-tested by browser vendors (Chrome, Firefox, Safari, Edge).echo adds a newline. echo abc | sha256sum hashes four bytes, "abc" plus a line feed, and prints edeaaff3f1774ad2888673770c6d64097e391bc362d7d6fb34982ddf0efd18cb. Use printf 'abc' or echo -n abc and you get ba7816bf...f20015ad, the same as typing abc here. In PowerShell, pipe strings through a file with no final newline, or hash the file with Get-FileHash.